CVE-2026-32959 affects the SD-330AC device and AMC Manager software from Silex Technology, Inc., stemming from the use of weak or broken cryptographic algorithms in network communications. The vulnerability allows attackers to intercept and retrieve sensitive information through man-in-the-middle attacks by exploiting the inadequate encryption implementation. With a CVSS score of 5.9 (Medium severity), the vulnerability requires network access but has high complexity requirements, resulting in confidentiality impact without affecting system integrity or availability. The vulnerability demonstrates minimal real-world exploitation activity, with no entries on the Known Exploited Vulnerabilities catalog and an extremely low EPSS score of 0.00018, indicating low probability of exploitation in the wild. Community attention remains low, though organizations operating affected Silex devices should prioritize patching to eliminate the potential for credential and data interception over the network.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.50CPE matchmatch criteria | cpe:2.3:o:silextechnology:sd-330ac_firmware:*:*:*:*:*:*:*:* | ||
< 5.1.0CPE matchmatch criteria | cpe:2.3:a:silextechnology:amc_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.